[CLSA-2022:1644869841] Fix of CVE: CVE-2021-34798, CVE-2021-39275, CVE-2021-36160, CVE-2021-44224
Type:
security
Severity:
moderate
Release date:
2022-02-14
Description:
- CVE-2021-44224: possible NULL dereference or SSRF in forward proxy configurations - CVE-2021-39275: out-of-bounds write in ap_escape_quotes() via malicious input - CVE-2021-36160: mod_proxy_uwsgi: out-of-bounds read via a crafted request uri-path - CVE-2021-34798: NULL pointer dereference via malformed requests
Updated packages:
  • httpd-2.4.37-39.module_el8.4.0+2006+b87b2deb.1.tuxcare.els3.x86_64.rpm
    sha:52287535f86acbe4d8c14f32184deaf624381863
  • mod_proxy_html-2.4.37-39.module_el8.4.0+2006+b87b2deb.1.tuxcare.els3.x86_64.rpm
    sha:2397534c9a4e83b418563aa0abe8d363ac62368e
  • httpd-manual-2.4.37-39.module_el8.4.0+2006+b87b2deb.1.tuxcare.els3.noarch.rpm
    sha:8fc8939d67f7fa52a05e000f7af1a578acffd619
  • httpd-tools-2.4.37-39.module_el8.4.0+2006+b87b2deb.1.tuxcare.els3.x86_64.rpm
    sha:a91473f81bac9077aff0dd6d86785821703e0fcc
  • mod_session-2.4.37-39.module_el8.4.0+2006+b87b2deb.1.tuxcare.els3.x86_64.rpm
    sha:a205fbed5ecae61d5768e98a238ba1b9c57ecf64
  • mod_ldap-2.4.37-39.module_el8.4.0+2006+b87b2deb.1.tuxcare.els3.x86_64.rpm
    sha:39c142d062dc3521fd1a7de08539eb3c3898bae3
  • httpd-filesystem-2.4.37-39.module_el8.4.0+2006+b87b2deb.1.tuxcare.els3.noarch.rpm
    sha:9a2cd76949306ded54b82e8108390f13b704b5a5
  • httpd-devel-2.4.37-39.module_el8.4.0+2006+b87b2deb.1.tuxcare.els3.x86_64.rpm
    sha:5c8a1e98daca368fb6344e838d83884027b612ae
  • mod_ssl-2.4.37-39.module_el8.4.0+2006+b87b2deb.1.tuxcare.els3.x86_64.rpm
    sha:2813dfc0d841adf86effbb993064417ed85ec314
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.